Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 26 of 78
CVE-2021-23960P3HIGHCVSS 8.8fixed in firefox 85.0-1 (sid)2021
CVE-2021-23960 [HIGH] CVE-2021-23960: firefox - Performing garbage collection on re-declared JavaScript variables resulted in a ...
Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
Scope: local
sid: resolved (fixed in 85.0-1)
debian
CVE-2021-38501P3HIGHCVSS 8.8fixed in firefox 93.0-1 (sid)2021
CVE-2021-38501 [HIGH] CVE-2021-38501: firefox - Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
Scope: local
sid: resolved (fixed
debian
CVE-2022-34484P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34484 [HIGH] CVE-2022-34484: firefox - The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbi...
The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Scope: local
debian
CVE-2023-6873P3HIGHCVSS 8.8fixed in firefox 121.0-1 (sid)2023
CVE-2023-6873 [HIGH] CVE-2023-6873: firefox - Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of...
Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.
Scope: local
sid: resolved (fixed in 121.0-1)
debian
CVE-2022-42928P3HIGHCVSS 8.8fixed in firefox 106.0-1 (sid)2022
CVE-2022-42928 [HIGH] CVE-2022-42928: firefox - Certain types of allocations were missing annotations that, if the Garbage Colle...
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Scope: local
sid: resolved (fixed in 106.0-1)
debian
CVE-2023-37202P3HIGHCVSS 8.8fixed in firefox 115.0-1 (sid)2023
CVE-2023-37202 [HIGH] CVE-2023-37202: firefox - Cross-compartment wrappers wrapping a scripted proxy could have caused objects f...
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Scope: local
sid: resolved (fixed in 115.0-1)
debian
CVE-2022-2505P3HIGHCVSS 8.8fixed in firefox 103.0-1 (sid)2022
CVE-2022-2505 [HIGH] CVE-2022-2505: firefox - Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs pres...
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.
Scope: local
sid: resolv
debian
CVE-2022-46878P3HIGHCVSS 8.8fixed in firefox 108.0-1 (sid)2022
CVE-2022-46878 [HIGH] CVE-2022-46878: firefox - Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fu...
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firefox ESR < 102.6
debian
CVE-2022-34483P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34483 [HIGH] CVE-2022-34483: firefox - An attacker who could have convinced a user to drag and drop an image to a files...
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34482. This vulnerability affects Firefox < 102.
Scope: local
si
debian
CVE-2022-34482P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34482 [HIGH] CVE-2022-34482: firefox - An attacker who could have convinced a user to drag and drop an image to a files...
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34483. This vulnerability affects Firefox < 102.
Scope: local
si
debian
CVE-2023-25735P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25735 [HIGH] CVE-2023-25735: firefox - Cross-compartment wrappers wrapping a scripted proxy could have caused objects f...
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2018-5095P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5095 [CRITICAL] CVE-2018-5095: firefox - An integer overflow vulnerability in the Skia library when allocating memory for...
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2022-45421P3HIGHCVSS 8.8fixed in firefox 107.0-1 (sid)2022
CVE-2022-45421 [HIGH] CVE-2022-45421: firefox - Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety b...
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Scope: l
debian
CVE-2022-46873P3HIGHCVSS 8.8fixed in firefox 108.0-1 (sid)2022
CVE-2022-46873 [HIGH] CVE-2022-46873: firefox - Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, ...
Because Firefox did not implement the unsafe-hashes CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.
Scope: local
si
debian
CVE-2022-28289P3HIGHCVSS 8.8fixed in firefox 99.0-1 (sid)2022
CVE-2022-28289 [HIGH] CVE-2022-28289: firefox - Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriel...
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunder
debian
CVE-2023-6866P3HIGHCVSS 8.8fixed in firefox 121.0-1 (sid)2023
CVE-2023-6866 [HIGH] CVE-2023-6866: firefox - TypedArrays can be fallible and lacked proper exception handling. This could lea...
TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always succeed. This vulnerability affects Firefox < 121.
Scope: local
sid: resolved (fixed in 121.0-1)
debian
CVE-2017-7785P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7785 [CRITICAL] CVE-2017-7785: firefox - A buffer overflow can occur when manipulating Accessible Rich Internet Applicati...
A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2023-28161P3HIGHCVSS 8.8fixed in firefox 111.0-1 (sid)2023
CVE-2023-28161 [HIGH] CVE-2023-28161: firefox - If temporary "one-time" permissions, such as the ability to use the Camera, were...
If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission persisted in that tab for all other documents loaded from a file: URL. This is potentially dangerous if the local files came from different sources, such as in a download directory. This vulnerability affects Firefox < 111.
debian
CVE-2022-46883P3HIGHCVSS 8.8fixed in firefox 107.0-1 (sid)2022
CVE-2022-46883 [HIGH] CVE-2022-46883: firefox - Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Moz...
Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 106. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.*Note*: This advisory was added on December 13th, 2022 after
debian
CVE-2022-28284P3HIGHCVSS 8.8fixed in firefox 99.0-1 (sid)2022
CVE-2022-28284 [HIGH] CVE-2022-28284: firefox - SVG's <code><use></code> element could have been used to load unexpected c...
SVG's element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied on this property for script security so gecko's implementation was aligned with theirs. This vulnerability affects Firefox < 99.
Scope: local
sid: resolve
debian